Exceptions to security policies are formally documented and approved
Sekit's Exception management policy, one of A.5.1's topic-specific policies, spells out how staff request, get approval for, and time-limit any deviation from the rules.
This policy control defines in writing how deviations from security policy are requested, approved and time-limited, the exception path A.5.36's compliance checking must account for.